← back
CVE-2017-3248

CVE-2017-3248

68Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 97%
from disclosure to weapon526 days
Published on NVDJan 27
1st PoC+526d
metasploitJan 25
exploitation probability
97%top 1% of all CVEs
observed exploitation
nono source reports it
6 public exploit(s)
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0 and 12.2.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS v3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).
Affected products
Oracle · WebLogic Server
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.